@hs-web-team/eslint-config-node
HubSpot Marketing WebTeam shared configurations for ESLint, Prettier, Stylelint, and Cypress
10
Versions
ISC
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
mhewittrymccartydmooneyleahshearerjcalleja-hubspotlopchannoriekelvinmrrraj_hubspotpwilverddingtstelmachhs_cfrisolipriedleamichelinilberginnhodgkiss447tshubhammanikraoannagallo-hslhampsoncutlahgwilliamshubspotcprinceaulfich-hssamson.yuwonovickytrandenishubspotmarkelly-hssgoldensonmndhlovusnigamandresllinasrconor_heffernankimccarthystevehealyadiazcometasasharmacayresiva_hmahad2ahiremathcwilliford_hubspotconormalonenmansurovcfritzhzahrambegynmlamacchiaraul_urdaneta_hsmariana.sanchez.sdamartinezralo_aloawilksleocifnpmmvalenciahubspothsnekingavincent-hubspotcleibert-hsericsalvidigarciahsdashdownscastro_hvalentinavelasquezjhubspotmheimjpcasanovagimineokaortizpgarbrechthsdevrelaswebsterdramonjmclarenjulianabuitrago
Keywords
eslintprettierstylelintcypresshubspotconfig
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): Runs a local peer-dep checker script; no network calls or arbitrary code execution. | ai | |
| phantom-deps | phantom-dep:prettier-plugin-gherkin | AI (phantom-deps): Prettier plugins are loaded by convention via prettier config, not direct import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:axe-core | AI (phantom-deps): axe-core is referenced in cypress config files, not directly imported; standard for eslint/cypress config packages. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): Binary dep used by cypress-esbuild-preprocessor; implicit runtime dep. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): ESLint config package; parser referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): ESLint config package; tools declared as deps but loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): ESLint config package; plugin referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:eslint-formatter-checkstyle | AI (phantom-deps): ESLint config package; formatter referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): ESLint config package; eslint is a peer/runtime dep loaded by convention. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): ESLint config package; prettier loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@eslint/eslintrc | AI (phantom-deps): Framework-scoped package loaded by ESLint convention, not direct import. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 4.2.2 | 19 / 0 | |
| 4.1.0 | 19 / 0 | |
| 4.0.2 | 19 / 0 | |
| 3.3.2 | 18 / 0 | |
| 3.3.0 | 18 / 0 | |
| 3.2.0 | 16 / 0 | |
| 3.1.3 | 13 / 0 | |
| 3.1.2 | 13 / 0 | |
| 3.1.1 | 13 / 0 | |
| 3.0.0 | 10 / 0 |
v4.1.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.